Disclosed are systems, apparatuses, methods, and computer-readable media for setting a network policy at a client device. A method includes: generating, by an agent of the client device, a profile for each process being executed; in response to receiving a first kernel event associated with a network connection to a destination address, identifying a first process associated with the first kernel event and a first profile corresponding to the first process; determining a source initiating the first kernel event based on the first profile of the first process and the first kernel event, wherein the source initiating the first kernel event comprises one of a user, the first process, and a second process that executes the first process; obtaining a network policy associated with the network flow; and communicating with the destination address using the network connection based on the network policy applied to the network flow
Legal claims defining the scope of protection, as filed with the USPTO.
generating, by an agent of the client device, a profile for each process being executed by the client device, wherein the profile for each process is generated based on information provided during kernel events; in response to receiving a first kernel event associated with a network connection to a destination address, identifying a first process associated with the first kernel event and a first profile corresponding to the first process, wherein the first kernel event is associated with a network flow of data to the destination address; determining a source initiating the first kernel event based on the first profile of the first process and the first kernel event, wherein the source initiating the first kernel event comprises one of a user, the first process, and a second process that executes the first process; obtaining a network policy associated with the network flow based on the source that initiated the first kernel event to apply to the network flow; and communicating with the destination address using the network connection based on the network policy applied to the network flow. . A method for setting network policies at a client device, the method comprising:
claim 1 . The method of, wherein the first kernel event is a socket event associated with a transmission control protocol connection or a universal data protocol connection.
claim 1 when the source that initiated the first kernel event corresponds to the user, determining if the user is accessing the client device using a remote connection. . The method of, further comprising:
claim 3 intercepting file system events and shell events initiated by the user based on the user accessing the client device using the remote connection; and applying a policy to the file system events and the shell events. . The method of, further comprising:
claim 4 applying a hook to a kernel interface to intercept and control a process event based on permitted controls specified in the network policy. . The method of, wherein applying the policy to the shell events comprises:
claim 4 applying a hook to a kernel interface to intercept a file system event and redirect the file system event to an empty file. . The method of, wherein applying the policy to the file system events comprises:
claim 1 identifying a collection of kernel events proximate to a time of the first kernel event; identifying a collection of user input events proximate to the time of the first kernel event; and determining the source based on comparing the collection of kernel events, the collection of user input events, and the first profile of the first process. . The method of, wherein determining the source initiating the first kernel event comprises:
claim 1 detecting a reclassification event based on a second kernel event associated with the first process, wherein the second kernel event indicates a change to the first process; and determining a source initiating the second kernel event based on the first profile of the first process. . The method of, further comprising:
claim 1 recording metadata associated with the network flow; and updating the first profile corresponding to the first process based on the metadata. . The method of, further comprising:
claim 9 . The method of, wherein the metadata includes at least one of process information of processes initiated by the first process, and network metadata associated with the network flow and data transmitted via the network flow.
a network device; and generate a profile for each process being executed by the client device, wherein the profile for each process is generated based on information provided during kernel events; in response to receiving a first kernel event associated with a network connection to a destination address, identify a first process associated with the first kernel event and a first profile corresponding to the first process, wherein the first kernel event is associated with a network flow of data to the destination address; determine a source initiating the first kernel event based on the first profile of the first process and the first kernel event, wherein the source initiating the first kernel event comprises one of a user, the first process, and a second process that executes the first process; obtain a network policy associated with the network flow based on the source that initiated the first kernel event to apply to the network flow; and communicate with the destination address using the network connection based on the network policy applied to the network flow. at least one processor coupled to the network device and configured to: . A client device for setting network policies, comprising:
claim 11 . The client device of, wherein the first kernel event is a socket event associated with a transmission control protocol connection or a universal data protocol connection.
claim 11 when the source that initiated the first kernel event corresponds to the user, determine if the user is accessing the client device using a remote connection. . The client device of, wherein the at least one processor is configured to:
claim 13 intercept file system events and shell events initiated by the user based on the user accessing the client device using the remote connection; and apply a policy to the file system events and the shell events. . The client device of, wherein the at least one processor is configured to:
claim 14 apply a hook to a kernel interface to intercept and control a process event based on permitted controls specified in the network policy. . The client device of, wherein the at least one processor is configured to:
claim 14 apply a hook to a kernel interface to intercept a file system event and redirect the file system event to an empty file. . The client device of, wherein the at least one processor is configured to:
claim 11 identify a collection of kernel events proximate to a time of the first kernel event; identify a collection of user input events proximate to the time of the first kernel event; and determine the source based on comparing the collection of kernel events, the collection of user input events, and the first profile of the first process. . The client device of, wherein the at least one processor is configured to:
claim 11 detect a reclassification event based on a second kernel event associated with the first process, wherein the second kernel event indicates a change to the first process; and determine a source initiating the second kernel event based on the first profile of the first process. . The client device of, wherein the at least one processor is configured to:
claim 11 record metadata associated with the network flow; and update the first profile corresponding to the first process based on the metadata. . The client device of, wherein the at least one processor is configured to:
claim 19 . The client device of, wherein the metadata includes at least one of process information of processes initiated by the first process, and network metadata associated with the network flow and data transmitted via the network flow.
Complete technical specification and implementation details from the patent document.
The disclosure relates generally to communication networks and, more specifically but not exclusively, to network policy of a client device based on machine or human control.
A remote connection agent, such as Cisco Secure Client, facilitates secure and seamless access to a company's private network infrastructure over the Internet. Similar remote connections agents use Identity Provider (IdP) integration to provide seamless authentication and access to enterprise networks, cloud services, and applications. This integration leverages protocols like security authentication markup language (SAML), OAuth 2.0, or OpenID Connect (OIDC) to enable secure and centralized identity management. The agents create a virtual private network (VPN) encrypted tunnel between the user's device and the corporate network and ensure that data transmitted between the user and the network remains confidential and protected from unauthorized access, even when using public or untrusted networks.
The agent typically functions through a combination of client-side software and server-side infrastructure. The agent, installed on the user's device, authenticates the user through credentials such as usernames, passwords, or multi-factor authentication (MFA). Once authenticated, the agent negotiates encryption protocols and establishes the VPN connection with a VPN gateway server hosted by the company. This gateway acts as a bridge between the remote user and the internal company network, allowing the user to access internal resources such as file servers, applications, and intranet sites as though they were physically on-site.
Various embodiments of the disclosure are discussed in detail below. While specific implementations are discussed, it should be understood that this is done for illustration purposes only. A person skilled in the relevant art will recognize that other components and configurations may be used without parting from the spirit and scope of the disclosure. Thus, the following description and drawings are illustrative and are not to be construed as limiting. Numerous specific details are described to provide a thorough understanding of the disclosure. However, in certain instances, well-known or conventional details are not described in order to avoid obscuring the description. References to one or an embodiment in the present disclosure may be references to the same embodiment or any embodiment; and, such references mean at least one of the embodiments.
Reference to “one embodiment” or “an embodiment” means that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the disclosure. The appearances of the phrase “in one embodiment” in various places in the specification are not necessarily all referring to the same embodiment, nor are separate or alternative embodiments mutually exclusive of other embodiments. Moreover, various features are described which may be exhibited by some embodiments and not by others.
The terms used in this specification generally have their ordinary meanings in the art, within the context of the disclosure, and in the specific context where each term is used. Alternative language and synonyms may be used for any one or more of the terms discussed herein, and no special significance should be placed upon whether or not a term is elaborated or discussed herein. In some cases, synonyms for certain terms are provided. A recital of one or more synonyms does not exclude the use of other synonyms. The use of examples anywhere in this specification including examples of any terms discussed herein is illustrative only and is not intended to further limit the scope and meaning of the disclosure or of any example term. Likewise, the disclosure is not limited to various embodiments given in this specification.
Without intent to limit the scope of the disclosure, examples of instruments, apparatus, methods, and their related results according to the embodiments of the present disclosure are given below. Note that titles or subtitles may be used in the examples for convenience of a reader, which in no way should limit the scope of the disclosure. Unless otherwise defined, technical and scientific terms used herein have the meaning as commonly understood by one of ordinary skill in the art to which this disclosure pertains. In the case of conflict, the present document, including definitions will control.
Additional features and advantages of the disclosure will be set forth in the description which follows, and in part will be obvious from the description, or may be learned by practice of the herein disclosed principles. The features and advantages of the disclosure may be realized and obtained by means of the instruments and combinations particularly pointed out in the appended claims. These and other features of the disclosure will become more fully apparent from the following description and appended claims, or may be learned by the practice of the principles set forth herein.
Disclosed are systems, apparatuses, methods, computer readable medium, and circuits for setting a network policy at a client device. According to at least one example, a method includes: building, by an agent of the client device, profiles associated with each process of the client device; in response to receiving a network connection request initiated by a process, classifying a source of the network connection request based on a profile corresponding to the process; obtaining a network policy associated with a network connection for the network connection request based on the source of the network connection request and the process; communicating with a destination identified in the network connection request based on the network policy. For example, the client device is configured to build profiles associated with each process of the client device; in response to receiving a network connection request initiated by a process, classify a source of the network connection request based on a profile corresponding to the process; obtain a network policy associated with a network connection for the network connection request based on the source of the network connection request and the process; and communicate with a destination identified in the network connection request based on the network policy. In some aspects, the source of the network connection request comprises at least one of a local user, a remote user, and process of the client device.
In some aspects, the agent can be part of a network authentication agent, such as a remote connection agent for securely connecting to private network infrastructure through a public network, or through a virtual private network (VPN).
In some aspects, different policies can be enacted based on whether the request is initiated through a remote interface (e.g., a remote connection) or a local interface (e.g., a physical interface such as a keyboard). For example, the client device may, based on the user accessing the network connection request, determine a context associated with a process being used through the remote interface; and intercept at least one of file system events and shell events corresponding to the context. In one example, the intercepting of the shell events comprises initiating a shell with limited access to a file system, memory, and network systems. In another example, the intercepting of at least one of the file system events comprises providing hooks the privileged agent to intercept the requests in files associated with the context and redirect the file system event to an empty file.
The client device can use a complex profile to identify the source of the network request. For example, the client device may check events proximate to a time of the network connection request; identify user input events proximate to the time of the network connection request; and based on identifying a user input or a process corresponding to an event that triggers the network connection request, determine the source of the network connection request. The client device may also detect a reclassification event associated with a process, wherein the reclassification event indicates a change of the source of the source of the network connection request; and determine a reclassification of the process.
There is no simple mechanism to distinguish between human-initiated and computer-initiated network data. Human-initiated data, such as browsing a website or sending an email, reflects deliberate actions and is often predictable in behavior and scale. In contrast, computer-initiated data, such as background updates, automated API calls, or malicious bot activities, can occur without user awareness, potentially leading to unexpected network congestion or security vulnerabilities.
Computer-initiated network data requests encompass a wide range of activities, both beneficial and potentially harmful. For example, automated software updates ensure applications and operating systems remain secure and functional, while background syncing of cloud storage services keeps files synchronized across devices. Additionally, sensors such as thermostats and security cameras periodically send data to their servers for monitoring and control. Malicious activities, such as botnet traffic executing Distributed Denial-of-Service (DDoS) attacks, can flood networks and disrupt services. Similarly, spyware and data exfiltration programs covertly send sensitive user data to unauthorized servers, compromising security and privacy.
Identifying the different types of network requests allows for prioritizing legitimate traffic, balancing requests to ensure workloads are efficiently allocated, and seamlessly allowing implementation of security measures. This is particularly important in automated environments where unchecked computer-initiated activities could overwhelm resources or expose systems to attacks like DDoS or data exfiltration.
In some aspects, systems, and techniques for setting a network policy at a client device are disclosed. In one illustrative aspect, an enhanced Berkely Packet Filter (eBPF), which is available across different operating systems (OSs), may be enabled at a client device to identify traffic that originates at that client and classify the origination of that traffic. In one aspect, an agent can include instructions to build profiles associated with each process of the client device and, in response to receiving a network connection request initiated by a process, classify a source of the network connection request based on a profile corresponding to the process. Notably, processes can quickly switch from human to computer control and the agent is configured to classify the network requests based on the profile as being human-initiated or machine-initiated using the profiles. The profiles can cross-reference different information (e.g., inputs), and network request information (e.g., destination address) to build a rich understanding of the classification. Based on the classification, the agent may set policies pertaining to the type of traffic. For example, the agent may limit the bandwidth of certain transactions, such as file synchronization services, but increase the bandwidth of others, such as sending an email with a large attachment.
Those of ordinary skill in the art will realize that the following description is illustrative only and is not intended to be in any way limiting. Reference will now be made in detail to implementations of examples as illustrated in the accompanying drawings. The same reference indicators will be used throughout the drawings and the following description to refer to the same or like items.
1 FIG. 100 110 120 110 112 114 116 120 120 122 124 120 is a conceptual illustration of a systemand accessing a private network using an agent in accordance with some aspects of the disclosure. A client devicemay be configured to access a private network. The client devicemay include an operating system (OS) such as operating systemexecuting at least one application such as application, and includes an agentto exchange authentication credentials with the private network. The private networkmay include an identity providerand at least one service such as service(e.g., a cloud service). In some aspects, aspects of the private networkare excluded for clarity.
120 130 116 132 116 122 110 122 122 116 132 To access the private network, a user may input authentication credentialsvia the agent, which exchanges authentication credentialsand other information, such as various certificates to provide an identity of the agent. The identity providerreceives the authentication credentials and may authenticate the client devicefor access. Although a single factor is illustrated, the identity providermay have multiple authentication factors such as sending private codes, requiring execution of external authentication functions, and so forth. The identity providerresponds to the agentindicating success as part of the authentication credentials.
116 110 120 114 134 124 136 114 112 138 124 140 At the end of the authentication flow initiated by the agent, the client deviceis configured to have access to the private network. For example, the applicationmay send a requestto the service, which provides a responsefor the applicationto consume. In some aspects, the operating systemitself (or an integrated application, a library, etc.) may send a requestto the service, which returns a response.
122 120 120 In this case, the identity provider(and corresponding infrastructure such as a firewall) are unable to distinguish between requests that are initiated by the applications under the control of users or by applications under the control of the system or some other aspect (e.g., a software updater). In some cases, being able to distinguish between the different types of traffic, such as in a private network, can have significant benefits. For example, the private networkcan block data requests from machine-based instructions to scrape or retrieve a volume of information, thereby implementing a data loss prevention (DLP) to prevent leakage of confidential internal assets.
116 116 In some aspects, an agentmay be extended to differentiate whether network traffic is initiated by a user or the system (e.g., an internal process) by including a privileged agent. For example, the agentmay include a bytecode-based packet filter (not shown) that may obtain privileged access to the system, such as by using eBPF. The packet filter may insert system calls or kernel hooks related to networking, such as connect( ), sendto( ), or write( ) at the kernel level and map information to the user space. For example, the packet filter may use the hooks to trace the source process initiating the traffic and then capture process identifiers, user identifiers, and command-line arguments. By correlating this data with process lineage, the privileged agent may determine if the network connection requests stems from user-initiated actions (e.g., a browser or manual script) or system-level processes (e.g., daemons or background updates). The packet filter is lightweight and does not require modifying application code and may allow enhanced visibility into network activity, improved security by detecting anomalies such as malware-generated traffic, and the ability to fine-tune network policies for user-specific or system-level traffic.
2 FIG. 200 200 210 220 212 210 222 220 212 212 212 200 200 is a conceptual illustration of a systemthat implements bytecode-based packet filter to instrument an operating system or an application with additional functionality in accordance with some aspects of the disclosure. Instrumentation bytecode is computer object code that is interpreted into binary machine code to modify various aspects of software systems, such as to measure performance of various aspects of the system or supplement various functions. The systemis logically divided into a user spacewhere a user executes various operations, stores application information, and so forth, and a kernel spacewhere system events occur and is restricted for security to prevent malicious actors. In some aspects, bytecodecan be loaded into the user space, which is then provided to a verifierwithin the kernel spacethat analyzes the bytecodefor security functions and ensures that the instructions are constrained based on a plurality of rules. For example, in an eBPF filter, the bytecodeis analyzed for looping instructions and reverse branches and permits the bytecodeto operate based on not including looping instructions and reverse branches. Looping instructions and reverse branches can be used to comprise the security of the systemand therefore may be strictly prohibited. The verifier implements a plurality of rules to prevent malicious instructions that could compromise the security of the system(e.g., by gaining root or administrator access).
222 212 212 230 230 230 In the event the verifiervalidates the bytecode, the bytecodeis then provided to the eBPFfor system modification and instrumentation. In some aspects, the eBPFcan configure various triggers to enable supplemental functionality. In one example, the eBPFmay analyze a wireless 802.11 packet to determine if the 802.11 packet is a beacon (e.g., an 802.11K beacon), or if a network packet is flood traffic associated with a distributed denial of service (DDOS) attack.
230 212 212 212 230 212 232 234 236 238 In some aspects, the eBPFexecutes the bytecodeand performs various actions such as measuring latency, summarizing latency as a histogram, analyzing stack traces, network logging functions, sending in-band network data (e.g., on the same network interface that triggers the bytecode), sending out-of-band network data (e. g, on a different network interface that triggers the bytecode), etc. In one illustrative example, the eBPFmay include a just in time (JIT) compiler that converts the bytecode into machine instructions. In some aspects, the bytecodecan be attached to different sources such as kprobes, uprobes, tracepoints, and events.
232 234 236 238 232 238 The kprobesenable kernel dynamic tracing, the uprobesenable user level dynamic tracing, the tracepointsenable kernel static tracing, and the eventsenable time sampling and performance metrics. For example, the kprobescan be triggered by network events to enable intrusion detection functions, and the eventscan be configured to measure latency and system responsiveness, particularly under load.
230 214 240 216 210 240 230 In some aspects, the eBPFcan pass data back to user space as eventsor maps. In some aspects, the maps can generate various statisticswithin the user space(e.g., network performance, latency, etc.). In some aspects, the mapsmaps can implement arrays, associative arrays, and histograms, and are suited for passing summary statistics. In other cases, the eBPFcan provide instrumentation to provide information to external systems for supplemental reporting, add additional information to a report, etc.
230 Although an eBPFis described, the functionality described herein can also be added to non-Linux based systems with network protocol extensions. For example, a real-time OS may receive a network protocol extension to supplement and standardize network reporting, which can improve intrusion detection and other security functions. Other OS variants are implementing eBPF functionality.
3 FIG. 300 302 is a conceptual diagramof a network stack implemented on a client device using an agent to apply policies in accordance with some aspects of the disclosure. In some aspects, a client deviceincludes various abstractions that are used to separate concerns and provide an agnostic standard how network communication occurs between different systems. The network stack simplifies troubleshooting, improves interoperability between diverse devices and protocols, and allows modular development of networking technologies.
304 306 308 310 312 314 316 The network stack includes a physical layer, a data link layer, a network layer, a transport layer, a session layer, a presentation layer, and an application layer. Each of the layers is separated into discrete functions and provides functionality to enable a variety of communication services, from wireless local networking to cellular communications.
304 For example, the physical layerrepresents the transmission and reception of data across the physical medium such as a conductive medium (e.g., a physical network) or a lossy medium (e.g., a wireless channel). The physical layer transmits data and receives data in symbols and includes, for example, a modem to translate bits into symbols to transmit data into electricity, light, or radio signals and controls the rates at which the symbols are sent over the chosen medium.
306 304 306 The data link layeris configured to receive network data and encapsulate the network data into into frames for transmission at the physical layer. The data link layermanages connections between two different nodes, including setting up the connection, identifying and correcting any bit errors that occur at the physical layer, and terminating the connection once the session is complete.
308 320 308 308 The network layerreceives data from other layers and configures packets and is also responsible for routing network packets to destination IP addresses. In some aspects, an agentis configured to execute at the network layerand may be implemented by implementing hooks into drivers and other software modules that implement the network layer.
310 312 314 316 310 302 310 322 308 322 310 320 The transport layer, the session layer, the presentation layer, and the application layermay be referred to as a host layer, which are the various media layers at the device that separate different functions. The transport layeris configured to generate protocol data units that segment data for transmission or combine protocol data units into a stream of data that can be provided to the components of the client device. The transport layermay also include at least one policy such as policythat can be used to control a stream of data provided to the network layer. In some aspects, the policymay operate at the transport layerto provide a single point of control based on functions requested by the agent.
312 312 In some aspects, the session layermanages sessions between nodes and may include more application-specific functions such as session management and authentication functions. For example, the session layermay include setup, authentication, and termination of a network connection.
314 314 The presentation layeris configured to translate data from network data into the formats expected by an application. For example, encoding, decoding, and encryption are managed at the presentation layer.
316 The application layerincludes protocols designed for end-users and include, for example, hypertext transfer protocol (HTTP) and other application-specific functions.
320 310 320 310 320 The network stack illustrates the logical separation and how the different aspects of the network can be handled and shows an example of how an agentcan be implemented. In many cases, many of the layers are transparent. For example, socket requests can be directly requested at the transport layer. The agentis configured to transparently handle any requests at the transport layerin a consistent manner without requiring any further instrumentation in software. In this case, the agentcan access privileged functions to implement network policies transparently.
304 330 320 322 330 330 320 For example, the physical layermay physically interface with a network (not shown) to connect to a cloud service. The agentis configured to implement the policyto control requests to the cloud serviceand responses received by the cloud service. In some aspects, the agentis configured to analyze various information such as process identifiers, executable, user identifiers, arguments, and other information to assess whether.
320 As further described below, the agentmay also be able to access other privileged kernel functions, such as the file system and shell, to provide additional security.
4 FIG. 400 400 402 404 406 400 408 410 is a sequence diagram illustrating a systemincluding an agent applying policies and performing a context switch in accordance with some aspects of the disclosure. The systemincludes a client devicethat executes at least one process such as processand an agentconfigured to link network policy of a client device based on machine or human control. The systemalso includes an infrastructure nodethat serves policies in connection with connections to at least one remote device such as remote device(e.g., a cloud service, etc.).
406 402 412 406 406 400 406 406 406 In some aspects, the agentis configured to monitor processes associated with the client deviceat block. For example, the agentis privileged bytecode implemented with eBPF and may be configured to receive OS events such as process initiation, process termination, network connection requests, network connection tear down, etc. In this case, the agentis configured to profile each process on the systemand record data, such as events triggered by a process, the user identifier (uid) initiating the event, arguments associated with the event, etc. For example, the agentmay detect a shell command (e.g., “lsof” to list all open files) issued by a process and corresponding commands (e.g., a path to limit the lsof command). In another example, the agentmay detect an IP address associated with a network request, and determine that the network connection is based on a machine instruction or a human input event from a human input device. In some aspects, the agentis configured to determine whether the process and its events are associated with the machine itself (e.g., check software update) or with a human input event (e.g., request connection to a cloud service).
406 414 410 416 406 414 406 414 406 418 408 418 For example, the agentmay receive (e.g., based on a hook) a connection request messageto connect to the remote device. In response, at block, the agentis configured to ascertain a source of the connection request message. For example, the agentmay ascertain whether the source of the connection request messageis associated with a machine instruction or a human input event. The agentthen sends a network policy requestto the infrastructure node, and the network policy requestmay identify a source of the network request (e.g., machine instruction, human input event, etc.).
408 420 420 402 410 404 422 420 404 410 424 420 404 In response, the infrastructure nodeis configured to respond with a corresponding network policy. The corresponding network policyis configured based on the source of the network request and allows different parameters to be applied at the client deviceto control the interface with the remote device. For example, the processmay send a connection setup messageto establish a socket or other network connection (e.g., HTTP) including parameters based on the corresponding network policy. After forming the connection, the processand the remote devicecommunicate databased on the connection dictated by the corresponding network policy. The processmay also implement various controls to impede or accelerate the network connection.
426 428 406 404 406 430 408 432 408 406 402 404 424 410 In some aspects, an eventmay occur that can cause the agent to process a context change at block. For example, the agentcan detect that the processchanges control source from machine instruction to human input events (or vice-versa). Based on the context change, the agentcan send a network policyto the infrastructure nodeand receive a revised network policyfrom the infrastructure node. In this case, the agentcan transparently update the network policy within the client devicewithout any changes as the processexchanges datawith the remote device.
406 402 406 In this case, the agentis configured to transparently apply network policies at the client devicebased on the source of the events or instructions, allowing the agentto tailor network connections and policies based on whether a user is providing human input events through a human input device or whether the instructions are being pushed from the machine or other application the user is executing.
4 FIG. In the example illustrated inis premised based on a connection request for purposes of illustration and a network connection. In some aspects, the network policy can be applied at different levels of abstraction. For example, a network connection refers to an established communication link between two endpoints, such as a client and a server, over a network. A network connection can include different network flows over the communication links, and the network flow represents the aggregation of related packets sharing common characteristics generally based on the 5 tuple of source IP address, destination IP address, source port, destination port, and protocol. The network connection is tied to the actual stateful exchange of data between endpoints and a network flow abstracts data exchange across multiple packets and correspond to traffic patterns. Network flows are commonly used in monitoring and analytics to assess bandwidth usage, detect anomalies, or optimize routing without needing to track individual connections.
5 FIG. 500 is a flow diagramillustrating an agent configuring a sandbox for a process in accordance with some aspects of the disclosure.
500 406 402 4 FIG. 4 FIG. In some aspects, the flow diagrambegins with the agent (e.g., the agentin) profiling each process of the device (e.g., the client devicein). For example, the agent may periodically monitor the processes or inject a hook into the OS to invoke a function any time a process is invoked or terminated. In this way, the agent can build a profile over time that considers the system as it changes over time. The agent is configured to receive various contextual information such as a process identifier (pid) of the file being executed (file), a user identifier that triggered the process (e.g., which can be a pid, a user identifier, etc.), and arguments. In some cases, the agent can also detect the timestamp if available or can record a timestamp when the process was first detected.
502 504 The agent can use the various information from the processes and build a profile of events and inputs associated with the different processes at block. For example, a primary process can trigger tertiary processes, and the profile of the primary process can include how the tertiary processes are triggered, when human input device input is detected, and so forth. In this way, the agent can associate file system events, shell events, and network events with a profile and determine when human input events are driving the primary process and when internal events are driving the primary process. As an example, a list including processesis illustrated and shows process identifiers, executed file (e.g., executable), timestamps, arguments, and so forth that can serve as the basis of the profile for each process.
506 506 At block, the agent may detect that the human input events are triggered by a remote profile. For example, the agent may detect that the human input events are being driven based on human inputs at a remote device using a virtual network connection to the client device. In this case, the agent may sandbox the client device as further described below. In this case, blockis optional because the sandbox can be applied in various contexts.
508 510 510 510 510 5 FIG. At block, the agent may determine to apply a sandbox on the client device. For example, the agent may restrict permissions for the remote user. In this case, the agent may implement limits into system components based on a sandbox configuration. As shown in, the sandbox configurationallows only access to the user home directory (e.g., “~”) and denies other access, and may allow the remote user to read files and create files. However, the user may not be able to remove files. For example, the agent can implement a hook with the filesystem kernel drivers regarding a delete operation, which would intercept the instruction and drop the command. The sandbox configurationmay also limit shell access to various commands. For example, the shell access my default defer to deny operations unless explicitly listed in the sandbox configuration, which includes the ls, lsof, and pwd shell commands. In some aspects, the shell access can also be used to restrict or permit different arguments. For example, ls includes all arguments, lsof is limited to a single option, and pwd allows arguments of-d with any additional arguments and -f without any additional arguments.
512 510 At block, the agent uses the sandbox configurationand configures hooks for the eBPF filter to redirect instructions based on the sandbox configuration. In this respect, the agent can provide an additional extra layer of security precautions based on additional context information of the user, such as the remote user. In other cases, the sandbox can be applied in varying contexts, such as based on execution of a particular application.
6 FIG. 600 600 600 is a flow diagram of an example processfor linking network policy of a client device based on machine or human control in accordance with some aspects of the disclosure. In some aspects, the computing system may implement the processin conjunction with an agent. Although the agent is described as executing the processbelow, the agent is executing in conjunction with various components of a computing system.
602 504 5 FIG. At block, the agent (executing via the computing system) may generate a profile for each process being executed by the client device. In some aspects, the profile for each process is generated based on information provided during kernel events. For example, the kernel events (e.g., file system events, process events, etc. in the kernel space) can be mapped to the process and corresponding data (e.g., arguments, etc.) can be stored in the process profile to assess control information of the process (e.g., whether the process is performing a human-initiated action or a machine-initiated action). For example, the agent may record metadata associated with the network flow and update the first profile corresponding to the first process based on the metadata. As an example, the metadata may include at least one of process information of processes (e.g., the processesin) initiated by the first process, and network metadata associated with the network flow (e.g., average latency, transmission size, jitter, etc.) and data transmitted via the network flow.
In some aspects, the first kernel event is a socket event associated with a transmission control protocol connection or a universal data protocol connection. In some aspects, the agent may include an eBPF functionality to register hooks that are invoked on a kernel interface, such as connect( ), accept( ), or bind( ) applied to a network interface. An example of a hook, which can be considered a middleware that is executed based on any call to the kernel interface, is illustrated below.
TABLE 1 struct SockAddr { sa_family: u16, sa_data: [u8; 14], } #[tracepoint(name = ″ connect″)] pub fn connect_hook(ctx: TracePointContext) -> u32 { match try_connect_hook(ctx) { Ok(ret) => ret, Err(_) => 1, // Return non-zero to signal an error } } fn try_connect_hook(ctx: TracePointContext) -> Result<u32, u32> { // Extract syscall arguments let args: [u64; 5] = unsafe { mem::transmute(ctx.args( )) }; let sockaddr_ptr = args[1] as *const SockAddr; if sockaddr_ptr.is_null() { return Ok(0); } let sockaddr = unsafe { *sockaddr_ptr }; // Extract port if IPv4 if sockaddr.sa_family == libc::AF_INET as u16 { let port = u16::from_be_bytes([sockaddr.sa_data[0], sockaddr.sa_data[1]]); info!(&ctx, ″connect( ) called: port={ }″, port); } else { info!(&ctx, ″connect( ) called: non-IPv4 address″); } Ok(0) } //in the main loop: let program: &mut TracePoint = bpf.program_mut(″connect″).unwrap( ).try_into( )?; program.load( ) ?; program.attach(″syscalls″, ″connect″)?;
In Table 1, the public function connect_hook is added in the main program loop to connect the try_connect_hook into the execution pipeline of the connect( ) function, allowing it to be executed anytime connect( ) is called.
604 At block, the agent (executing via the computing system) may, in response to receiving a first kernel event associated with a network connection to a destination address, identify a first process associated with the first kernel event and a first profile corresponding to the first process. In this example, the first kernel event is associated with a network flow of data to the destination address. For example, the first kernel event may be associated with initiating a transmission of content, such as a OS triggered update event or a user triggered event.
606 At block, the agent (executing via the computing system) may determine a source initiating the first kernel event based on the first profile of the first process and the first kernel event. In one aspect, the source initiating the first kernel event comprises one of a user, the first process, and a second process that executes the first process. For example, the kernel event can be tied to a human input device event or closely correlated in time to the event (e.g., within microseconds). In one aspect, to determine the source initiating the first kernel event, the agent may identify a collection of kernel events (e.g. zero or more) proximate to a time of the first kernel event, identify a collection of user input events (e.g., zero or more) proximate to the time of the first kernel event, and determine the source based on comparing the collection of kernel events, the collection of user input events, and the first profile of the first process.
The agent may check events proximate to a time of the inputs associated with the process. For example, when a network request is provided, the agent analyzes other events proximate to the process such as identifying user input events proximate to the time of the network connection request. The absence of input events, for example, can indicate the presence of machine control. In some cases, the agent may be based on identifying a user input or a process corresponding to an event that triggers the network connection request, determining the source of the network connection request. The agent looks at a large number of factors, such as user identifiers, process identifiers, arguments, etc., to ascertain the source of the network request. All of this information is mapped into the profile of each process.
The comparison of the kernel events, the user input events, and the profile can occur a number of different ways, such as weighting of events based on time before the first kernel event, cross referencing available information, identifying patterns in the profile. As an example, a reducer, which is a function to filter and reduce data from one form into a different representation, can be implemented to identify pertinent data, generate a score based on cross-referencing data with the profile, and identify a probability of the kernel event being triggered by a user event. A reducer is just one example, there any various techniques that can be employed to analyze the data.
608 At block, the agent (executing via the computing system) may obtain a network policy associated with the network flow based on the source that initiated the first kernel event to apply to the network flow. For example, the agent may connect to a network infrastructure node that provides network policies per network connection or network policies per network flow.
610 At block, the agent (executing via the computing system) may communicate with the destination address using the network connection based on the network policy applied to the network flow. In some cases, the network connection can already be established, such as a persistent connection to object storage of an internal network. When a large transaction (e.g., upload) is requested with the object storage by a user, because the connection is requested by the user, the network policy can be configured to prioritize this transaction.
In some aspects, when the source that initiated the first kernel event corresponds to the user, the agent may also determine if the user is accessing the client device using a remote connection. If the user is accessing the client device, the agent may intercept file system events and shell events initiated by the user and applying a policy to the file system events and the shell events. For example, the agent may apply a hook (e.g., pipeline processing function) to a kernel interface (e.g., as shown above) to intercept and control a process event based on permitted controls specified in the network policy. A process event is an instruction to control a process lifecycle, such as spawn a process, kill a process, pause a process, and so forth. The kernel event can include signal triggered events (e.g., SIGKILL, SIGINT, SIGCHILD), input/output redirection via stderr or stdout, pipe communication, system call events such as fork( ) and child( ), timers, exception events, shell-specific events, etc. In another example, the agent may apply a hook to a kernel interface to intercept a file system event and redirect the file system event. For example, in response to a request to read a file, the hook can provide an empty file in response. In this manner, if the user is accessing via a remote interface, the agent can implement a sandbox and may limit access to the system.
In some aspects, the agent may detect a reclassification event associated with a process. For example, the agent may detect a significant amount of human input device provided to the process, which is at least partially indicative of human input events. Based on the reclassification event, the agent detecting a reclassification event based on a second kernel event associated with the first process and then determine a source initiating the second kernel event based on the first profile of the first process. For example, the agent may request the network policy from an infrastructure node based on the reclassified source. In this manner, the agent is capable of dynamic switching based on a profiling the processes, mapping inputs, and stateful observation of the processes.
7 FIG. 7 FIG. 7 FIG. 700 710 700 710 750 illustrates a logical diagram of memory space of an operating system (OS) in accordance with an embodiment. In particular,illustrates that a user spaceand a kernel spaceare separated by a logical barrier to isolate application and system resources for security purposes and system purposes. Specifically,illustrates data from the user spaceand a kernel spaceare mapped into the physical memory. The physical memory can be implemented by any suitable random access memory (RAM) such as static RAM (SRAM) or synchronous dynamic RAM (SDRAM).
A modern operating system can implement a virtual memory that collects and manages memory from a collection of memory devices (e.g., non-volatile hard disk or other non-volatile storage media to provide additional program memory) to create a virtual memory, a protected memory, and a shared memory. A virtual memory is a collection of all memories, a protected memory provides exclusive access to a region of memory that is allocated to a process, and a shared memory provides cooperative access to a region that is shared by multiple processes.
Memory is configured in distinct units and can vary based on the type of memory. For example, a hard disc allocates blocks in 512 bytes intervals and a Linux kernel allocates a page of memory in 4096 byte intervals.
7 FIG. 702 700 704 706 712 704 706 In the example illustrated in, a plurality of applications such as applicationthat execute within the user spaceand may call an application programming interface (API) such as APIor may use a common language runtime (CLR) such as CLR(e.g., java, C #, webassembly) to access the kernel subsystemsin the kernel space. The APIof the CLRcan implement logic to manage the heap, which is a dynamically sized memory that changes during runtime (e.g., as the application executes).
702 706 702 706 704 712 704 706 For example, an applicationwritten in C #may use the CLRto perform a network request to another device. The applicationitself includes instructions that are executed by the CLRor APIto interact with the kernel subsystems. In this case, the APIor the CLRmanages the heap of the application.
712 702 706 706 712 714 716 716 The kernel subsystemsalso provide access to hardware devices. For example, the applicationincludes instructions for the CLRto execute a network request. In this case, the CLRgenerates and provides the request to the kernel subsystems, which provides suitable instructions to a device driverto perform the network request using the device. For example, the devicecould be a network interface to execute an HTTP get request for specific data (e.g., a request to retrieve a web page).
702 712 704 706 702 704 716 In some cases, an applicationmay implement its own heap management functions and directly interact with the kernel subsystemswithout the APIor the CLR. Although not illustrated, such an applicationmay operate with an APIon a selective basis to perform some functions (e.g., interaction with devices) but omit other aspects (e.g., heap management).
712 720 750 720 722 724 726 The kernel subsystemsuses a virtual machine (VM) such as VMto handle management of the physical memoryand perform access (e.g., read/write) functions. The VMcomprises a slab allocator, a zone allocator, and a buddy allocatorfor controlling memory allocation and access.
726 726 740 750 726 740 726 726 740 The buddy allocatorallocates physically contiguous blocks of memory within the entire system. Specifically, the buddy allocatorallocates pages and maps each page into a memory management unit (MMU) such as MMUthat performs the read and write operations in the physical memory. The buddy allocatorreceives a memory request and maps the request to a valid physical address range for the MMU. The buddy allocatorreceives a request for a memory allocation and thereby allocates pages of memory. The buddy allocatorprefers to allocate contiguous portions of memory for applications. In some hardware configurations, the MMUmay not be present and may be implemented by a software module.
724 The zone allocatoris used to allocate pages in different zones that are designed by the OS. For example, zones can include a direct memory access (DMA) zone, a normal zone, and a high memory zone. The DMA zone is provided for direct memory operations of legacy devices. The normal zone includes memory addresses used by the kernel for internal data structures as well as other system and user space allocations. The high memory zone is used for allocation of system resources (e.g., file system buffers, user space allocations, etc.).
722 724 722 The slab allocatorcan provide finer control by creating pages and segmenting the pages into caches that are initialized by the zone allocator. In some examples, the slab allocatorcreates different caches for each object type (e.g., inode_cache, dentry_cache, buffer_head, vm_area_struct) for storing each object in the corresponding cache.
720 728 730 750 730 732 734 The VMmay also include a swapand a flushthat are used for maintaining the swap, which is conventionally used to handle memory addressing when the physical memorybecomes largely or fully utilized. The flushmay interact with a storage driver, which stores swap content in a non-volatile storage.
710 750 734 702 700 700 710 710 700 710 The kernel spaceis controlled and only accessible to the kernel because it provides all mechanisms to access the physical memoryand the non-volatile storage. The various applications such as applicationstore data within the user space. The user spaceand kernel spaceare separated to isolate separate concerns and provide a security barrier to prevent applications from intentionally or unintentionally writing in the kernel space. For example, in the example of the network request, the C #application is not concerned about the implementation details of the network request (e.g., a WebSockets request) and is concerned about whether the request is successful or not. Therefore, the user spacecontains the application information for the network request and the kernel spacestores information required to implement that network request.
710 710 710 The kernel spaceimplements security precautions and attempts to prevent access by applications to prevent intentional and unintentional malicious memory access from occurring. For example, the kernel spacemay attempt to prevent a row hammer attack, which is a repeated bit-flipping of a row of memory addresses to attempt to cause neighboring bits to unintentionally flip values due to electromagnetic effects of repeated bit flipping. Row hammer attacks can be used to escalate user privileges so that a malicious entity can access the kernel space.
720 700 710 702 710 The VMis an example of a memory management system that manages the physical memory and separates application content in the user spaceand system content in the kernel space. Another OS may implement a memory management subsystem differently but use similar concepts to provide a layer of system security to prevent applications such as applicationfrom being able to access the kernel space.
7 FIG. In some instances, the processor and/or the system itself may include additional devices to provide additional layers of security. For example, the processor, which is not illustrated in, may include a secure register that is not available for general use and has security precautions. For example, a processor may include a secure configuration register (SCR) that can be programmed during a boot sequence with a security score. A specific hardware component may be configured to calculate the security score during the boot sequence and store that score in the SCR.
8 FIG. 800 110 200 302 402 805 805 810 805 shows an example of computing system, which can be for example any computing device making up the client device, the system, the client device, the client deviceand other devices described herein, or any component thereof in which the components of the system are in communication with each other using connection. Connectioncan be a physical connection via a bus, or a direct connection to processor, such as in a chipset architecture. Connectioncan also be a virtual connection, networked connection, or logical connection.
800 In some embodiments, the computing systemis a distributed system in which the functions described in this disclosure can be distributed within a datacenter, multiple data centers, a peer network, etc. In some embodiments, one or more of the described system components represents many such components each performing some or all of the function for which the component is described. In some embodiments, the components can be physical or virtual devices.
800 810 805 815 820 825 810 800 812 810 In one example, computing systemincludes at least one processing unit (CPU or processor) such as processorand connectionthat couples various system components including system memory, read-only memory (ROM) such as ROMand random access memory (RAM) such as RAMto processor. Computing systemcan include a cache of high-speed memoryconnected directly with, in close proximity to, or integrated as part of processor.
810 832 834 836 830 810 810 Processorcan include any general purpose processor and a hardware service or software service, such as services,, andstored in storage device, configured to control processoras well as a special-purpose processor where software instructions are incorporated into the actual processor design. Processormay essentially be a completely self-contained computing system, containing multiple cores or processors, a bus, memory controller, cache, etc. A multi-core processor may be symmetric or asymmetric.
800 845 800 835 800 800 840 To enable user interaction, computing systemincludes an input device, which can represent any number of input mechanisms, such as a microphone for speech, a touch-sensitive screen for gesture or graphical input, keyboard, mouse, motion input, speech, etc. Computing systemcan also include output device, which can be one or more of a number of output mechanisms known to those of skill in the art. In some instances, multimodal systems can enable a user to provide multiple types of input/output to communicate with computing system. Computing systemcan include communications interface, which can generally govern and manage the user input and system output. There is no restriction on operating on any particular hardware arrangement, and therefore the basic features here may easily be substituted for improved hardware or firmware arrangements as they are developed.
830 Storage devicecan be a non-volatile memory device and can be a hard disk or other types of computer readable media which can store data that are accessible by a computer, such as magnetic cassettes, flash memory cards, solid state memory devices, digital versatile disks, cartridges, random access memories (RAMs), read-only memory (ROM), and/or some combination of these devices.
830 810 810 805 835 The storage devicecan include software services, servers, services, etc., that when the code that defines such software is executed by the processor, it causes the system to perform a function. In some embodiments, a hardware service that performs a particular function can include the software component stored in a computer-readable medium in connection with the necessary hardware components, such as processor, connection, output device, etc., to carry out the function.
For clarity of explanation, in some instances, the present technology may be presented as including individual functional blocks including functional blocks comprising devices, device components, steps or routines in a method embodied in software, or combinations of hardware and software.
Any of the steps, operations, functions, or processes described herein may be performed or implemented by a combination of hardware and software services or services, alone or in combination with other devices. In some embodiments, a service may be software that resides in memory of a client device and/or one or more servers of a content management system and perform one or more functions when a processor executes the software associated with the service. In some embodiments, a service is a program, or a collection of programs that carry out a specific function. In some embodiments, a service may be considered a server. The memory may be a non-transitory computer-readable medium.
In some embodiments the computer-readable storage devices, mediums, and memories may include a cable or wireless signal containing a bit stream and the like. However, when mentioned, non-transitory computer-readable storage media expressly exclude media such as energy, carrier signals, electromagnetic waves, and signals per se.
Methods according to the above-described examples may be implemented using computer-executable instructions that are stored or otherwise available from computer readable media. Such instructions may comprise, for example, instructions and data which cause or otherwise configure a general-purpose computer, special purpose computer, or special purpose processing device to perform a certain function or group of functions. Portions of computer resources used may be accessible over a network. The computer executable instructions may be, for example, binaries, intermediate format instructions such as assembly language, firmware, or source code. Examples of computer-readable media that may be used to store instructions, information used, and/or information created during methods according to described examples include magnetic or optical disks, solid state memory devices, flash memory, USB devices provided with non-volatile memory, networked storage devices, and so on.
Devices implementing methods according to these disclosures may comprise hardware, firmware and/or software, and may take any of a variety of form factors. Typical examples of such form factors include servers, laptops, smartphones, small form factor personal computers, personal digital assistants, and so on. Functionality described herein also may be embodied in peripherals or add-in cards. Such functionality may also be implemented on a circuit board among different chips or different processes executing in a single device, by way of further example.
The instructions, media for conveying such instructions, computing resources for executing them, and other structures for supporting such computing resources are means for providing the functions described in these disclosures.
Although a variety of examples and other information was used to explain aspects within the scope of the appended claims, no limitation of the claims should be implied based on particular features or arrangements in such examples, as one of ordinary skill would be able to use these examples to derive a wide variety of implementations. Further and although some subject matter may have been described in language specific to examples of structural features and/or method steps, it is to be understood that the subject matter defined in the appended claims is not necessarily limited to these described features or acts. For example, such functionality may be distributed differently or performed in components other than those identified herein. Rather, the described features and steps are disclosed as examples of components of systems and methods within the scope of the appended claims.
Cooperative Patent Classification codes for this invention. Click any code to explore related patents in that topic.
February 13, 2025
August 13, 2026
Browse 5M+ US patents with plain-English claim translations and AI-generated analysis.